Disable MAC Randomization is a per ssid setting in MDMs, so you are not disabling privacy for devices when they are used on other networks and as you are saying they don't leave campus, I'm not sure what the concern is. They are your devices, on your network. What makes them any different in that scenario from a wired desktop? They just happen to be on wireless.
... View more